In which case putting in a simple hits/IP rate limiter with something like nginx is probably enough to defend against this for the future.
https://nginx.org/en/docs/http/ngx_http_limit_req_module.htm...